Sectrio

Healthcare

Understanding the significance of the latest “cyberattack” on AIIMS

Deciphering the latest attack on AIIMS    

In the latest edition of our threat landscape report, Sectrio’s threat researchers had done a comprehensive analysis of the Indian cyber threat landscape, the actors, tactics, malware, and enablers. This report also highlighted the alarming levels of sophistication and maturity demonstrated by state-backed hackers that are targeting Indian critical infrastructure, businesses, and financial services infrastructure. The findings of the report do paint a realistic picture of how fast things are changing in cyberspace vis-à-vis threats, breach tactics, and targets In this piece, we will look at how and why some of the institutions in India are being repeatedly stalked and targeted in cyberspace. We recommend that this article be read in conjunction with the threat report for you to gain a complete understanding and context of the data presented here. As per the data trail left by hackers, Indian cyberspace has been extensively targeted since 2011. In that year, there were a couple of significant events recorded here that were unprecedented in magnitude and portended the scale of events to come. Since 2011, threat actors have expanded their presence in the country while scaling up their operations to cover more sectors and profiles of persons of interest. In addition to critical infrastructure, several of the procurement and production cycles of many vendors connected with defense supply chains, high-end manufacturing, and government agencies are also being targeted The AIIMS attack is certainly not an isolated one. Here are a few significant cyber incidents that occurred in the last few years.  What really happened at AIIMS?  As per media reports on the incident, it has been said that a cyber breach has been ruled out and the incident involved “someone trying to access E-hospital, an internal application” belonging to the premier healthcare institute. It is also said that the application is not accessible from the Internet. In subsequent reports, however, it was claimed that there was an incident involving a weakened server. The questions that arise are: When one puts the above information available publicly, a clearer picture of the attack emerges. At a primary level, the latest cyberattack on AIIMS is designed to send a message. “The hackers can strike at will even at targets that have been breached before and have since been hardened”.  This attack also seems to have been carried out using data exfiltrated during the last attack and has since been shared possibly with other state-backed threat actors within China. Actors like APT 41 are acting to gain and retain access to critical systems and data that can be used to target institutions and key decision-makers in times of peace or during a geopolitical event. The latest attack could have been an attempt to gain access to some updated records or delete some information residing in the weakened server or it could have been an attempt to exfiltrate data of interest residing on this server.   The writing is clearly on the wall. The second attack represents a continued threat actor and adversarial state interest in key Indian institutions  Check out: The Global OT and IoT Threat Landscape Assessment and Analysis Report 2023

Deciphering the latest attack on AIIMS     Read More »

Dissecting the cyber incident at All India Institute of Medical Sciences (AIIMS)

Dissecting the cyber incident at All India Institute of Medical Sciences (AIIMS) 

The news of the All India Institute of Medical Sciences (AIIMS) servers being breached is making headlines across India. While the full extent of the data that was compromised and the actors who are behind it are still unknown, we do have some clues on what this attack entails for the healthcare segment in India and beyond. Our threat research team has drawn the following inferences after studying the attack on AIIMS and its aftermath. Disclaimer: these inferences are based on the data and the information we have gathered from published sources on the surface and dark web as of December 5th. Some inferences are subject to change based on new data made available. Since the breach is under investigation from CERT-in, the inferences drawn may be subject to change after the investigation report is made public.

Dissecting the cyber incident at All India Institute of Medical Sciences (AIIMS)  Read More »

The truth about cyberattacks on the healthcare sector in India

The truth about cyberattacks on the healthcare sector in India

Cyberattacks on the healthcare sector in India are rising and there are many reasons for this. Right now, India is ranked 11th among the top 20 most targeted nations in the healthcare sector in the world. The IoT and OT global threat landscape assessment report 2022 While the sector has attracted attention from APT actors globally, most attacks are still driven by unaffiliated or loosely affiliated actors who are after a ransom. Healthcare providers, insurers, and even small clinics and online pharma companies are being targeted to obtain information and to target providers and service users.  Data criticality and the cost of systems force healthcare organizations to pay up the ransom just to get back on their feet.   While some data is floating around on the volume of attacks on this sector in India, we have not seen any data being shared on the actual attacks that were occurring.  This is why we have put this post together. a) to help healthcare industry participants understand the nature of the evolving threat landscape in the country and b) to drive awareness on the urgent need to respond to the rising cyber threats and to prevent more attacks from occurring.   Here are the top trends and data on attacks on the healthcare sector in India: Why is the healthcare sector being targeted in India? There are many reasons for this. Here are a few: With such a complex modus-operandi, it comes as no surprise that Indian healthcare providers and victims are bleeding PII and more. Such information once leaked will return to haunt the victim and the provider. Sign up for our one-on-one threat intelligence and security landscape briefing to learn more about such attacks. Join our Cybersecurity Awareness Month campaign Find out what is lurking in your network. Go for a comprehensive 3 layer threat assessment now See our solution in action through a free demo

The truth about cyberattacks on the healthcare sector in India Read More »

Scroll to Top